Attackers are complicating tactics, using multi-vector schemes, AI-based tools, and rented cloud servers to generate traffic.
In the first five months of 2026, the number of DDoS attacks in Russia and CIS countries increased by 27% compared to the same period last year. Kaspersky Lab announced this at the St. Petersburg International Economic Forum.
Experts note that incidents have become not only more frequent but also more powerful: the peak power of individual attacks increased by 173%, and the number of attacks with an intensity exceeding 200 Gbps grew by 215%.
The most attacked sectors remain telecommunications, finance, and government organizations. Vyacheslav Kirillov, Product Manager for Kaspersky DDoS Protection, noted:
We observe a steady trend towards the complication of DDoS attacks. Attackers are increasingly using long-term and multi-vector scenarios aimed not at short-term service disruption, but at gradual infrastructure exhaustion.
The first surge of attacks occurred in February, when their average duration exceeded two days, and some continued for more than two weeks. A second, more powerful peak was observed in April amid the activation of botnets and DDoS-as-a-Service platforms. At the same time, in May, the total number of incidents stabilized, but their complexity continued to grow, shifting towards targeted campaigns.
A key technical trend was the increase in application-layer (L7) attacks, which accounted for 51%. Such attacks mimic the actions of real users, making them difficult to filter. In addition, bots have learned to bypass standard protective mechanisms, including CAPTCHA.
